Method · provenance

How to read a UIOLI proof packet

This packet is substantiation evidence for a spending-account claim. It is not a payment, not an enrollment record, and not a certification of eligibility.

Dual-claim

Two parties speak. The member asserts that the expense is a qualified medical cost. The engine documents what it did: line items, Pub 502 categories, tiers, LMN presence, hashes, engine version. The TPA stamps — approve, deny, or needs-letter — under the plan’s authority. UIOLI never holds the rubber stamp.

Advisory vs authoritative

Anything the phone showed at capture is advisory fail-fast UX. The service re-checks eligibility, dates, and balance. Do not treat an on-device hint as the determination in this file.

Tiers

A TPA rule can be as simple as: auto-approve when every line is Eligible and attested; refer the rest.

Provenance

Each packet names how the receipt was read (on-device Vision vs any later ingress), confidence when recorded, and hashes of evidence bytes. If a field says an engine or confidence that your process does not use, treat that as a defect in the record, not as decoration.

Service date (when care was incurred) is the eligibility date. Purchase date may differ. Both should appear when known.

Engine documentation: current · https://uioli.co/how

Webhooks

After a TPA stamps or denies a packet, UIOLI POSTs JSON {"event":"stamped"|"denied","packetId"} to each HTTPS endpoint the TPA registered. Header x-uioli-signature is HMAC-SHA256 of that body (sha256=<hex>), using the same secret as bind tokens. Failed delivery does not undo the decision. Loopback and private hosts are not called.

If you administer this plan, you can receive these packets by API or webhook. Integrate